DRUPAL-CONTRIB-2024-012

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/private_content/DRUPAL-CONTRIB-2024-012.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-012
Aliases
  • CVE-2024-13248
Published
2024-02-28T18:19:01Z
Modified
2025-12-10T23:41:28.608828Z
Summary
[none]
Details

This module gives each node a 'private' checkbox. If it's set, the node can only be seen by the node author, or users with the 'access private content' permission.

The module incorrectly grants access to private nodes under certain specific circumstances. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Access private content".

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/private_content

Package

Name
drupal/private_content
Purl
pkg:composer/drupal/private_content

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0
Database specific
{
    "constraint": "<2.1.0"
}

Database specific

affected_versions
"<2.1.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/private_content/DRUPAL-CONTRIB-2024-012.json"